Affected versions

This XSS vulnerability affects GitLab 7.2.0 and earlier.

Impact

The vulnerability patched by this release allows an attacker to carry out a cross-site scripting (XSS) attack against users with a session on an affected GitLab server. In order to exploit this vulnerability, the attacker needs to have commit access to a repository on the affected GitLab server.